Input validation error in etcd - #VU130099
Published: August 5, 2020 / Updated: May 5, 2026
etcd
CoreOS
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in parseCompactionRetention in embed/etcd.go when processing a negative auto compaction retention value. A local user can supply a negative retention value to cause a denial of service.
The issue can trigger a history compaction loop, resulting in increased CPU usage and log spam.